Certificate Identification Data Extraction for Mobile Message Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for retrieving certificates in encrypted messages are inefficient, particularly on mobile devices, as they require downloading the entire message to identify the sender's certificate, which is time-consuming and bandwidth-intensive, especially when only a part of the message has been downloaded or if the message is too long.

Innovation Solution

A system and method that generates certificate identification data from the message, allowing for partial message retrieval and processing to determine the sender's certificate without downloading the entire message, by using hash algorithms or parsing serial numbers and issuer data to identify and retrieve the correct certificate from certificate servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the entire message is downloaded to retrieve the sender's certificate, then the certificate can be identified and verified, but the bandwidth consumption and time required increase significantly

Engineering Contradiction:
Improvecertificate identification accuracyVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts only the necessary certificate identification data (such as certificate serial number and/or issuer information) from the message without downloading the entire message. This allows the mobile device to query certificate servers for the required certificate using minimal data, thereby reducing bandwidth consumption while maintaining reliable certificate identification.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If the entire message is downloaded to retrieve the sender's certificate, then the certificate can be identified and verified, but the time required increases significantly

Engineering Contradiction:
Improvecertificate identification accuracyVSAvoidcertificate retrieval time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts only the necessary certificate identification data from the message, enabling the mobile device to immediately query certificate servers without waiting for the entire message to download. This significantly reduces the time required to retrieve and verify the sender's certificate.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary extraction of certificate identification data from the message before initiating the certificate retrieval process. This preliminary action allows the system to prepare and send minimal query information to certificate servers, reducing the overall time required for certificate verification.

Inventive Principle:
Principle #10Preliminary action

3Loss of energy

If only partial message data is downloaded, then bandwidth consumption is reduced, but the ability to identify the required certificate with certainty is compromised

Engineering Contradiction:
Improvebandwidth consumptionVSAvoidcertificate identification accuracy
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent applies local quality by extracting only the specific portions of the message that contain certificate identification information (such as serial numbers and issuer data) while ignoring the rest of the message content. This selective extraction maintains sufficient reliability for certificate identification while minimizing bandwidth consumption.

Inventive Principle:
Principle #3Local quality

4Measurement precision

If certificate search is performed manually by user input, then search precision can be controlled, but the ease of operation decreases and time consumption increases

Engineering Contradiction:
Improvecertificate search accuracyVSAvoiduser operation simplicity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent implements self-service by automatically extracting certificate identification data from the received message and initiating the certificate search process without requiring manual user input. The system autonomously queries certificate servers using the extracted data, significantly improving ease of operation while maintaining search accuracy through automated processing.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7549043B2Providing certificate matching in a system and method for searching and retrieving certificates
Publication Date: 2009.06.16 MALIKIE INNOVATIONS LTD
  • US7549043B2 patent drawing
  • US7549043B2 patent drawing
  • US7549043B2 patent drawing

AI summary

A system and method for searching and retrieving certificates, which may be used in the processing of encoded messages. In one broad aspect, a message management server generates certificate identification data from a message that uniquely identifies a certificate associated with the message. The certificate identification data can then be used to determine whether a given located certificate retrieved from one or more certificate servers in response to a certificate search request is the certificate associated with the message. Only the certificate identification data is needed to facilitate the determination at a user's computing device (e.g. a mobile device), alleviating the need for the user to download the entire message to the computing device in order to make the determination.